Executive brief
cgltf is a library used by developers to load and process 3D models in the glTF format. A flaw in how the library validates specific 3D data structures (sparse accessors) allows a specially crafted file to bypass security checks. If an application uses this library to open a malicious 3D model, it could result in a program crash or the unauthorized disclosure of sensitive information from the computer's memory.
Technical details
An integer overflow vulnerability exists in cgltf versions <= 1.15 within the `cgltf_validate()` function. The root cause is unchecked arithmetic operations when calculating `indices_req_size` and `values_req_size` for sparse accessors; specifically, `indices_component_size * sparse->count` can wrap around `size_t`, causing the library to accept undersized buffers. An attacker can provide a crafted glTF/GLB file with large `count` values to trigger this overflow, leading to a heap buffer over-read in `cgltf_calc_index_bound()`. This can result in a process crash (DoS) or memory disclosure. A patch has been proposed in the project's repository to implement proper overflow checks and clamping.
Affected products
- jkuhlmann cgltf 1.15 and prior
Timeline
- 2026-03-23: disclosed: Vulnerability reported via GitHub issues
- 2026-03-23: advisory
- 2026-05-04: patched: Pull request 293 submitted to fix the overflow